Cyber Resilience

CVE-2014-8684

Kohanaframework Kohana 3.2.3 … 3.3.1

Public PoCHigh EPSS
Published
19 September 2017
Modified
20 April 2025
CVSS Score v3 9.8
Click a component to see what it means
Raw vectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.72 99.4th percentile
Risk Priority 97 floored blend · peak EPSS

Summary

CVE-2014-8684 is a critical-severity an unspecified weakness vulnerability in Kohanaframework Kohana. Its CVSS base score is 9.8 (Critical).

Operationally, ranked in the top 0.6% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

EU & UK References

Vulnerability Data

CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof session cookies and consequently conduct PHP object injection attacks by leveraging use of standard string comparison operators to compare cryptographic…

more

hashes.

CWE(s)

Related Threats

Likely ATT&CK TechniquesAI

Techniques this vulnerability likely enables, inferred from its description, weakness type, and attributed-actor tradecraft. Confidence is per-technique.

T1556 Modify Authentication Process Defense Impairmentconfidence: MEDIUM
Weak hash comparison enables forging or tampering with session tokens used for authentication.
inferred from description + CWE · MITRE ATT&CK Enterprise v19.0

CVEs Like This One

CVE-2023-46240Same product: Codeigniter Codeigniter
CVE-2024-41344Same product: Codeigniter Codeigniter
CVE-2024-29904Same product: Codeigniter Codeigniter
CVE-2025-24013Same product: Codeigniter Codeigniter
CVE-2025-54418Same product: Codeigniter Codeigniter
CVE-2023-32692Same product: Codeigniter Codeigniter
CVE-2024-20690Shared CWE-310
CVE-2026-49000Shared CWE-310
CVE-2023-23919Shared CWE-310
CVE-2024-38408Shared CWE-310

Affected Assets

codeigniter
codeigniter
≤ 2.2.6
kohanaframework
kohana
3.2.3, 3.3.0, 3.3.1

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References